View online: https://www.drupal.org/sa-contrib-2019-069
Project: Gutenberg [1] Date: 2019-September-25 Security risk: *Critical* 16∕25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:All [2] Vulnerability: Access bypass
Description: This module provides a new UI experience for node editing - Gutenberg editor.
The routes used by the Gutenberg editor lack proper permissions allowing untrusted users to view and modify some content they should not be able to view or modify.
Solution: Install the latest version:
* If you use the Gutenberg module 8.x-1.x, upgrade to 8.x-1.8 [3] * For roles other than administrator, the Administer Gutenberg permission must be given to handle media files on the Gutenberg editor.
Also see the Gutenberg [4] project page.
Reported By: * Marco Fernandes [5] * Greg Knaddison [6] of the Drupal Security Team
Fixed By: * Marco Fernandes [7] * Thor Andre Gretland [8] * Mariusz Andrzejewski [9]
Coordinated By: * Greg Knaddison [10] of the Drupal Security Team
[1] https://www.drupal.org/project/gutenberg [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/gutenberg/releases/8.x-1.8 [4] https://www.drupal.org/project/gutenberg [5] https://www.drupal.org/user/2127558 [6] https://www.drupal.org/user/36762 [7] https://www.drupal.org/user/2127558 [8] https://www.drupal.org/user/223878 [9] https://www.drupal.org/user/3517832 [10] https://www.drupal.org/user/36762